3 ms·
It would only matter to cryptographic code if an implementation somehow used floating-point, but the source-level conversion from floating-point to unsigned int
by pascal_cuoq 9y ago
It would only matter to cryptographic code if an implementation somehow used floating-point, but the source-level conversion from floating-point to unsigned integer can also leak information in execution time when translated to x86 code:
https://godbolt.org/g/LqUDir https://godbolt.org/g/LqUDir
Other implementations purely in hardware or purely in software would be constant-time, but the x86, only offering an instruction for the conversion to signed integer, leads to a mixed solution in which the short sequence of instructions generated by compilers contains a conditional branch on the value being converted.